Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kisaragieffective

#21518of 53,630
11.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-28437
6.5
2024-07-01
Toy-Blog · Toy-Blog · CVE-2024-39313
**Name of the Vulnerable Software and Affected Versions** toy-blog versions 0.5.4 through 0.6.0 **Description** The issue allows articles with private visibility to be read without proper credentials. This can lead to unauthorized access to sensitive information. Users are advised to upgrade to a newer version to receive the necessary patch. **Recommendations** For toy-blog versions 0.5.4 through 0.6.0, upgrade to version 0.6.1 or later to resolve the issue.
PT-2024-28438
4.7
2024-07-01
Toy-Blog · Toy-Blog · CVE-2024-39314
**Name of the Vulnerable Software and Affected Versions** toy-blog versions 0.4.3 through 0.4.14 toy-blog versions prior to 0.4.14 **Description** The administrative password is leaked through the command line parameter. This issue was patched in version 0.5.0. **Recommendations** For versions 0.4.14 and later, pass `--read-bearer-token-from-stdin` to the launch arguments and feed the token from the standard input as a workaround. For versions prior to 0.4.14, update to version 0.5.0 to resolve the issue. For versions 0.4.3 through 0.4.13, update to version 0.5.0 to resolve the issue.